CVE-2025-41351: Funambol Cloud Server

Medium severity, CVSS 6.0. EPSS: 0.2% chance of exploitation in the next 30 days.

Vulnerability that allows a Padding Oracle Attack to be performed on the Funambol v30.0.0.20 cloud server. The thumbnail display URL allows an attacker to decrypt and encrypt the parameters used by the application to generate ‘self-signed’ access URLs.

Affected products

  • Funambol Cloud Server: version 30.0.0.20 only

Published 2026-01-28. Last modified 2026-06-17.